Major Flaw - Delete Homebase data via camera

Wow. I was just about to purchase their 2k doorbell and a few cameras. After seeing this major flaw, I will no longer be making the purchase and I will now be looking at alternative brands. Thanks for bringing this to people’s attention, it’s a shame eufy don’t see this matter is important. The lack of response/action will put me off buying any of eufy’s products going forward.

Yea I know very disappointing from eufy. I already invested a lot in their security infrastructure so am reluctant to throw it away but it’s very worrying and I certainly won’t buy anything else from them!

The thing is it’s such a simple firmware update, either add some 2FA or make it that you need to verify the reset on the doorbell via the homebase.

As soon as one thief learns about this flaw, then it will spread like wildfire :pensive:

I could also imagine some juveniles resetting people’s doorbells for a laugh too…to be fair, if any of my mates have them I may do it to wind them up :joy:

Its not so simple because of the way Eufy designed their hardware. The Sync button is designed to get you out of hung processes and allow return to factory state. If the device cannot communicate, you can’t use 2FA to validate the operation. Once it’s been Sync’d record key is lost for any existing video. The clips still exist, but cannot be retrieved. They did try to mitigate the issue with a software update that kept the existing video using a different key, but ran into other issues and rolled it back.

I am sure its fixable, but they don’t want to devote the resources to fixing it. Not even sure they have the necessary expertise to generate a fix. Instead of at least fixing the issue in newer hardware, they have just ignored it and migrated the flaw into all their new products.
Pretty lame.

Hi, Eufy released EufyCam 3. Any update on if this camera contains a Sync button and if yes is it different compared to previous versions or the same?

Please share if you have any information. Thanks!

I am curious about whether the flaw still persists in new products as well. I know every cam released before the Homebase 3 generation still carries the flaw. If I had to bet, I’d bet Homebase 3 gear does too.

However, not curious enough to spend good money on a system to test. I’ve had enough of Eufy.

Hi,

I am really shocked and disappointed about the 10 seconds sync button video erase “feature”. I have contacted Eufy about this and the answer is ridiculous (it’s designed to keep customers information secure). I really hope that Eufy changed this feature, but I am not really hopeful. Maybe when all customers complain abouth this, Eufy would listen…

People have been complaining about this flaw since Jan. 21. Eufy has gone from “working as designed”, which everyone called bullshit on, to we need 3-4 months to fix it. After 6 months passed, they went back to “working as designed”. Now, you get a number of different excuses, but essentially they aren’t going to fix it. They don’t care that this flaw makes Eufy gear look like a child’s toy instead of a security system.

Thank god I stumbled over this. Was about to jump onto the eufy train by buying around $1000 worth of equipment, but this really kills the deal. Working in tech myself I get it, bugs exist. But seeing how poorly this issue has been handled and how long they’ve been aware of it, that’s just inexcusable. Nothing “security” about this type of conduct. Nobody seems to know if the latest iteration (eufy 3) has this issue too, but the failure of handling this appropriately makes me not even interested in it anymore. How to lose out on sales, I suppose… A shame, because otherwise it seemed quite compelling.

Glad to see this post is still helping people 18 months on.

I wonder if any of this has been fed back to Eufy by the moderators of this forum… :thinking:

Not sure if anybody tried.

Is it possible to disable this sync button hardware or dummy it from the eufy 3 camera?

Oh no just buyed the new dual doorbell. Thank god I haven’t opened it yet so I will send it back tomorrow! I was going to buy two Eufycams 3 as well. But with this major bug I will buy a different security system from another company.

This is so ridiculous!

I spoke with Eufy on live chat about it this week, the CS rep didn’t have a clue what I was talking about but said he had passed my concerns on to their technical department and that they would be in touch. The tech dept did contact me and they asked me to describe the major security flaw. This was my response to them:

My concerns are regarding the below:

Major Flaw - Delete Homebase data via camera - Queries - Eufy Security Collective

How can this be a feature included by design? Basically, someone could walk onto my property and damage or steal whatever they want and then all they have to do is remove the camera or any other cameras, press the sync button for 10 secs then all evidence of them ever being there is gone! How is that a security system?

Also they could keep the £200+ cameras and then either sell them or connect them to their own system and no one is any the wiser. How can a camera be so easily removed from a person’s system without the admin of that system giving approval? It invites people to steal the cameras, why should I buy one when I can nip down the street remove theirs, hold sync to wipe the footage and then install it on my system. Hey presto free camera.

No other major brand has this feature which is just ridiculous by design. It’s a fundamental security flaw.

I have seen thousands of posts regarding this across many forums including Eufy’s own, its also now being featured on YouTube reviewers’ videos:

My question is do you have any intention of addressing your customers and potential customers concerns about this?

You are losing an unquestionable number of sales due to this fundamental flaw by design, I was going to purchase the new Eufy Cam 3 with homebase 3 until I found out this. Now I am looking at another brand for my house security requirements, I will also be removing the Eufy products I currently have as I cannot trust the product. Until this issue is resolved I’m afraid myself and who knows how many more thousands of people will no longer purchase or use Eufy products.

This was brought to your attention almost 2 years ago and still nothing has been done.

Listen to your customers, without your customers you have no brand.

Today I received a reply:

Safety is always the core of the eufy brand. Thank you so much for your attention and feedback for us!

We have set up a special engineering team to conduct technical solutions to ensure this issue can be resolved, ASAP. In order to provide the stability of the system and the safety of all users. Our engineering team is not only tackling problems quickly but also doing a complete test and evaluation. Ensure the safety of every eufy user.

In fact, all eufy Camera recording data is stored locally and encrypted. Only the user can access it through the eufy Security account.

Our action plan, “press and hold 10s on the Sync button erase binding and settings feature” will be canceled.

If you have any questions, you are more than welcome to contact us at any time!

Reference TicketTNW386461594 if contacting a CSR

Yong Gates

Eufy Customer Support Engineer

Promising response but actions speak louder than words. I guess we will see.

5 Likes

Don’t hold your breath. This is exactly the same type of response that I received from Eufy when I did an exhaustive test of their devices and forwarded the results to them. I wasn’t the first to find the issue, but I was the first to do the test on door sensors and motion detectors as well as cameras that also have sync issues. I opened a ticket in March 2020 and was told their engineering team was working the issue, but it would take 2- 3 months to fix. When I didn’t hear from them after 3+ months, they said it was a complex issue and they needed another 3-4 months. After that, they closed my ticket and support went back to " working by design". Don’t expect Eufy to fix this. They couldn’t give a shit about their customers, just the next buck.

What is the timeline of this fix. I bought 8 cameras. Planning to return all of them.

There will be no fix…… Eufy have been aware of this issue for over 2 years now and their position is that it is a design feature to protect users data not a bug or fault. Pathetic tbh. Wish I had never bought into their ‘security system’

1 Like

Bought a 2k doorbell eufy cameras on Black Friday and after testing, I decided to return it. I do like them, the price, all the functions, but with the ‘sync’ flaw i would not say this is a security camera, is more like a video cam to me.

Has anyone seen this?

Specifically:

Currently, you are only allowed to remove the S330/S300 eufyCam(eufyCam 3/3C) from HomeBase 3 by using the eufySecurity App, rather than pressing the camera’s SYNC button for 10

That is a start, no?

1 Like

Let’s hope this will be kept. If I read “currently” it seems they are trying to allow this in the future.

My Solo OutdoorCam’s C24 received an firmware update today.
Info on the update stating that holding the SYNC button down for 10 seconds will not reset the cam.
Could this be a start for a fix?

EDIT: I just realized, if your cameras have on board storage its own memory or SD card that it records to then this firmware update for the SYNC button would not apply, if a perp was going to try to erase the footage why not just take the whole cam? This update should not have gone out to the Solo Cams.
The fix would only apply to videos that record onto the HomeBase.